Regulation S-P: Safeguards, Incident Response, and the Notification Clocks
In plain language
Regulation S-P says you have to protect customer information, know when it has been exposed, and tell people about it on a clock. The 2024 amendments turned the last part into a written program with deadlines: customers get notified within 30 days of you becoming aware, and your vendors have to tell you within 72 hours of becoming aware. Almost all of the work is knowing where customer information actually lives before anything goes wrong.
What Regulation S-P actually requires
Regulation S-P (17 CFR Part 248) has three operating parts that a technology program has to answer for.
Privacy notices and opt-out. The firm tells customers what it does with nonpublic personal information and gives them a way to limit some sharing. This part is mostly a disclosure exercise, but it constrains technology in one important way: if the notice says information is not shared with a category of third party, the systems have to actually behave that way.
The Safeguards Rule. 17 CFR 248.30(a) requires written policies and procedures containing administrative, technical, and physical safeguards reasonably designed to protect customer records and information. “Reasonably designed” is the whole game. There is no control list to check off, which means the defensible position is a documented decision about each risk rather than a product purchase.
The Disposal Rule. 17 CFR 248.30(b) requires reasonable measures to protect against unauthorized access in connection with the disposal of consumer report information. In practice this is about hardware and media leaving the building, and about what a cloud tenant does with deleted data.
What the 2024 amendments added
The SEC adopted amendments to Regulation S-P in May 2024 (Release 34-100155, press release). They apply to broker-dealers, investment companies, SEC-registered investment advisers, funding portals, and registered transfer agents. Three things changed materially.
A written incident response program is now required
The safeguards policies must include a written incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. It has to include procedures for assessing the nature and scope of an incident, containing and controlling it, and notifying affected individuals.
The word doing the work is written. Many firms already had an escalation habit — a call tree, an MSP on retainer, an understanding that the CCO gets told. None of that is an incident response program until the assessment and notification procedures exist on paper and someone has approved them.
Customers get notified within 30 days
Notice must be provided as soon as practicable, and no later than 30 days after the firm becomes aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred. The notice describes the incident, the information involved, and what the affected person can do.
Thirty days is an outer bound, not a target, and it starts at awareness rather than at confirmation. That has a practical consequence for logging: if you cannot determine whose information was reached, you cannot narrow the notification population, and the safe answer becomes the broad one. Log retention is therefore a notification-cost control, not just a security control.
Service providers get 72 hours
The firm must have written policies and procedures reasonably designed to require its service providers to take appropriate measures to protect against unauthorized access to customer information, including notifying the firm as soon as possible and no later than 72 hours after becoming aware of a breach in a system maintaining customer information.
The rule binds the firm, so the mechanism is contractual. A service provider that has not agreed to the 72-hour clause is not going to discover the obligation on its own. See vendor and service-provider oversight for how to run the register that makes this auditable.
Compliance dates
The amendments give larger covered institutions 18 months and smaller covered institutions 24 months from Federal Register publication. Measured from the June 3, 2024 publication date, that is December 3, 2025 for larger covered institutions and June 3, 2026 for smaller ones. Firm-size definitions are in the release; they are not the same thresholds used elsewhere in the Advisers Act rules, so read them rather than assuming.
Where firms usually find the gap
The pattern is consistent, and it is rarely the firewall.
- Customer information in places nobody inventoried. Exported spreadsheets, a years-old file share, the CRM’s attachment store, an advisor’s personal archive of client statements, a marketing tool that received a client list once.
- Logs that expire before they are needed. A 30-day retention default means an incident discovered in week six cannot be scoped.
- Vendor agreements that predate the clause. The 72-hour obligation is missing from every contract signed before the firm started asking for it, which is usually most of them.
- An incident response program that does not name the notification decision-maker. The containment steps are written and the disclosure step says “notify as required.”
How this connects to the rest of the program
The Safeguards Rule is the substantive obligation, and Advisers Act Rule 206(4)-7 is the rule that requires you to have policies and review them. For advisers, a Regulation S-P failure usually shows up as a 206(4)-7 finding as well. Broker-dealers should read this alongside FINRA supervision and cybersecurity.
The incident response half of this section is developed further in incident response and exam evidence, and the access side in access control and MFA.
Pylon’s service pages cover the same ground from the delivery side: Regulation S-P compliance and RIA cybersecurity.
Primary sources
Frequently Asked Questions
When does the 30-day Regulation S-P notification clock start?
It starts when the firm becomes aware that unauthorized access to, or use of, customer information has occurred or is reasonably likely to have occurred. Notice must go out as soon as practicable and no later than 30 days after that point. The clock is not tied to when the incident happened or when the investigation finished.
Does Regulation S-P apply to registered investment advisers, or only broker-dealers?
Both. The amended rule applies to broker-dealers, investment companies, SEC-registered investment advisers, funding portals, and transfer agents registered with the Commission. The compliance dates differ by firm size, not by registration type.
What is the difference between Regulation S-P and Regulation S-ID?
Regulation S-P is about safeguarding and disposing of customer information and notifying people when it is exposed. Regulation S-ID is about detecting and responding to the misuse of that information to commit identity theft. The same systems tend to produce evidence for both, which is why firms often run one program with two reporting views.
Does a service provider have to notify us in 72 hours, or do we have to put that in the contract?
Practically, the contract is how it happens. The rule requires the covered institution to have written policies and procedures reasonably designed to require service providers to provide notification as soon as possible and no later than 72 hours after becoming aware of a breach. If the agreement is silent, the obligation is not operative for that vendor and the firm has a gap to close.
Scheduled actions
The recurring work this section implies. Each action carries a stable
action-id so it can be tracked in a compliance calendar and rolled up on
all scheduled actions.
Re-verify the inventory of systems and vendors that store, process, or can reach customer information, including anything added by a new tool, integration, or acquisition.
- Cadence:
- Quarterly
- Owner archetype:
- CCO, MSP
- Source:
- 17 CFR 248.30
- action-id:
act.reg-s-p.customer-info-inventory-review
Review and re-approve the written incident response program, including the assessment, containment, and notification procedures, and record who approved it.
- Cadence:
- Annually
- Owner archetype:
- CCO
- Source:
- SEC Release 34-100155
- action-id:
act.reg-s-p.ir-program-review
Run a tabletop that exercises the customer notification decision specifically: who determines scope, who drafts the notice, who approves it, and how the 30-day clock is documented.
- Cadence:
- Annually
- Owner archetype:
- CCO, MSP
- Source:
- SEC Release 34-100155
- action-id:
act.reg-s-p.notification-tabletop
Confirm every service provider with access to customer information is under an agreement carrying the 72-hour breach notification obligation, and log the exceptions that are still open.
- Cadence:
- Annually
- Owner archetype:
- CCO, IT
- Source:
- SEC Release 34-100155
- action-id:
act.reg-s-p.service-provider-clause-audit
Verify that decommissioned media, retired endpoints, and expired records containing consumer report information were disposed of under the Disposal Rule, and keep the certificates.
- Cadence:
- Quarterly
- Owner archetype:
- IT, MSP
- Source:
- 17 CFR 248.30(b)
- action-id:
act.reg-s-p.disposal-verification
Before a new system goes live, determine whether it will hold customer information and, if it will, add it to the inventory and bring it under the safeguards and notification program.
- Cadence:
- On change
- Owner archetype:
- IT, MSP
- Source:
- 17 CFR 248.30
- action-id:
act.reg-s-p.new-system-scope-check
Configuration touchpoints
Where this section lands in a real environment. Each touchpoint is stated as a plain
configuration rule — not a vendor setting — and carries a stable config-id.
| Configuration rule | Applies to | config-id |
|---|---|---|
| Every system, share, mailbox, and vendor that can reach customer information appears in one inventory with a named owner and a recorded last-review date. | Asset and data inventory | cfg.reg-s-p.customer-info-inventory |
| Customer information is encrypted where it is stored and whenever it moves outside the firm's network, including email containing account numbers. | Endpoints, file storage, email gateway | cfg.reg-s-p.encryption-at-rest-and-in-transit |
| Access to systems holding customer information is logged, and those logs are retained long enough to reconstruct who saw what during an incident investigation. | Identity provider, file storage, line-of-business applications | cfg.reg-s-p.access-logging-retained |
| Alerts that would indicate unauthorized access to customer information route to a monitored queue with a defined response time, not to an individual's inbox. | SOC / monitoring platform | cfg.reg-s-p.breach-detection-alerting |
| For each in-scope service provider, the firm records the channel a 72-hour breach notice would arrive on and who monitors it outside business hours. | Vendor register | cfg.reg-s-p.vendor-notification-contact |
| Media and devices that held customer information are wiped or destroyed to a documented standard before leaving the firm's control. | Endpoint lifecycle, decommissioning process | cfg.reg-s-p.secure-disposal |
More in the Compliance Library
- Advisers Act Compliance and Cybersecurity: Rule 206(4)-7 and the Technology Program
- Books and Records: Electronic Retention Under Rule 17a-4 and Rule 204-2
- FINRA Supervision and Cybersecurity: Rule 3110 and Broker-Dealer Technology Controls
- Regulation S-ID: Identity Theft Red Flags, at a High Level
- Vendor and Service-Provider Oversight for Regulated Financial Firms
- Access Control and MFA for RIAs, Broker-Dealers, and Funds
- Incident Response and Exam Evidence for Financial Firms
- Private Fund and PE Adviser Technology Notes
Rollups: all scheduled actions and monitor and review.
- Author
- Rachel Lannon and Byron Foley
- Reviewed by
- Tim Quinn
- Last updated
This is operational technology guidance for regulated firms, not legal advice. Confirm how each requirement applies to your firm with your compliance counsel.